Contrôle du document
- Version
- First Version
- Numéro de version
- 1.0.0
- Date
- 1 November 2024
| Nom | Fonction |
|---|---|
| Fredrick ALUNALA | Consultant |
| APPROVALS | |
| Paul ODIMBA | Director General |
| PROCESS EXECUTORS | |
| Gervais MILANDOU | Shareholder |
Policy Statement
IMF Bisou Bisou SA (hereinafter referred to as the “Company”) needs to collect personal information to effectively carry out our everyday business functions and activities and to provide the products and services defined by our business type. Such data is collected from employees, customers, suppliers and clients and includes (but is not limited to), name, address, email address, IP address, identification numbers, private and confidential information and sensitive Know Your Customer (KYC) information.
In addition, we may be required to collect and use certain types of personal information to comply with the requirements of the law and/or regulations, however we are committed to processing all personal information in accordance with the General Data Protection Regulation (GDPR) and any other relevant the data protection laws and codes of conduct (herein collectively referred to as “the data protection laws”).
The company has developed policies, procedures, controls and measures to ensure maximum and continued compliance with the data protection laws and principles, including staff training, procedure documents, audit measures and assessments. Ensuring and maintaining the security and confidentiality of personal and/or special category data is one of our top priorities and we are proud to operate a 'Privacy by Design' approach, assessing changes and their impact from the start and designing systems and processes to protect personal information at the core of our business.
Purpose
The purpose of this policy is to ensure that IMF Bisou Bisou meets its legal, statutory and regulatory requirements under the data protection laws and to ensure that all personal and special category information is processed compliantly and in the individual’s best interest.
The data protection laws include provisions that promote accountability and governance and as such IMF Bisou Bisou has put comprehensive and effective governance measures into place to meet these provisions. The aim of such measures is to ultimately minimize the risk of breaches and uphold the protection of personal data. This policy also serves as a reference document for employees and third-parties on the responsibilities of handling and accessing personal data and data subject requests.
Scope
This policy applies to all staff within IMF Bisou Bisou (meaning permanent, fixed term, and temporary staff, any third-party representatives or sub-contractors, agency workers, volunteers, interns and agents engaged with IMF Bisou Bisou), and pertains to the processing of personal information. Adherence to this policy is mandatory and non-compliance could lead to disciplinary action.
Definition
- “Biometric data” means personal data resulting from specific technical processing relating to the physical, physiological or behavioral characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data.
- “Binding Corporate Rules” means personal data protection policies which are adhered to by the Company for transfers of personal data to a controller or processor in one or more third countries or to an international organization.
- “Consent” of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
- “Cross Border Processing” means processing of personal data which:
- takes place in more than one Member State; or
- which substantially affects or is likely to affect data subjects in more than one Member State
- “Data controller” means, the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
- “Data processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
- “Data protection laws” means for the purposes of this document, the collective description of the GDPR, Data Protection Bill and any other relevant data protection laws that the Company complies with.
- “Data subject” means an individual who is the subject of personal data
- “GDPR” means the General Data Protection Regulation (EU) (2016/679)
- “Genetic data” means personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question.
- “Personal data” means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- “Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.
- “Recipient” means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in
accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.
- “Supervisory Authority” means an independent public authority which is established by a Member State
- “Third Party” means a natural or legal person, public authority, agency or body other than the data subject, under our direct authority
General Data Protection Regulation (GDPR)
As IMF Bisou Bisou processes personal information regarding individuals (data subjects), we are obligated under the General Data Protection Regulation (GDPR) to protect such information, and to obtain, use, process, store and destroy it, only in compliance with the data protection laws and its principles.
Personal Data
Information protected under the GDPR is known as “personal data” and is defined as: - “Any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.”
IMF Bisou Bisou ensures that a high level or care and measures are afforded to personal data falling within the GDPR’s ‘special categories’ (previously sensitive personal data), due to the assumption that this type of information could be used in a negative or discriminatory way and is of a sensitive, personal nature to the persons it relates to.
In relation to the ‘Special categories of Personal Data’ the GDPR advises that: - “Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited – unless one of the Article 9 clauses applies.”
The GDRP Principles
Article 5 of the data protection laws requires that personal data shall be:
- processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’)
- collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’)
- adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimization’)
- accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’)
- kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organizational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’)
- processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures (‘integrity and confidentiality’).
Objectives
IMF Bisou Bisou committed to ensuring that all personal data processed by the Company is done so in accordance with the data protection laws and its principles, along with any associated regulations and/or codes of conduct laid down by the Supervisory Authority and local law. We ensure the safe, secure, ethical and transparent processing of all personal data and have stringent measures to enable data subjects to exercise their data protection rights.
IMF Bisou Bisou has developed the below objectives to meet our data protection obligations and to ensure continued compliance with the regulatory requirements.
The Company ensures that: -
- We protect the rights of individuals with regards to the processing of personal information
- We develop, implement and maintain a data protection policy, procedure, audit plan and training program for compliance with the data protection laws
- Every business practice, function and process carried out by the Company, is monitored for compliance with the data protection laws and its principles
- Data is only processed where we have met the lawfulness of processing requirements
- We only process special category data in accordance with the GDPR regulations and in compliance with the Data Protection Bill Schedule 1 requirements
- We record consent at the time it is obtained and evidence such consent to the Supervisory Authority where requested
- All employees (including new starters and agents) are competent and knowledgeable about their GDPR obligations and are provided with in-depth training in the data protection laws, principles, regulations and how they apply to their role and our business
- Individuals feel secure when providing us with personal information and know that it will be handled in accordance with their rights under the data protection laws
- We maintain a continuous program of monitoring, review and improvement with regards to compliance with the data protection laws and to identify gaps and non-compliance before they become a risk
- We have robust and documented Complaint Handling and Data Breach controls for identifying, investigating, reviewing and reporting any breaches or complaints with regards to data protection
- We have appointed a Carol Williams who takes responsibility for the overall supervision, implementation and ongoing compliance with the data protection laws and performs specific duties as set out under Article 37 of the GDPR.
- We have a dedicated Audit & Monitoring Program in place to perform regular checks and assessments on how the personal data we process is obtained, used, stored and shared. The audit program is reviewed against our data protection policies, procedures and the relevant regulations to ensure continued compliance
- We provide clear lines of reporting and supervision with regards to data protection
- We store and destroy all personal information, in accordance with the data protection laws timeframes and requirements
- Any information provided to an individual in relation to personal data held or used about them, with be provided in a concise, transparent, intelligible and easily accessible form, using clear and plain language
- Employees are aware of their own rights under the data protection laws and are provided with the Article 13 & 14 information disclosures
- Where applicable, we maintain records of processing activities in accordance with the Article 30 requirements
- We have developed and documented appropriate technical and organizational measures and controls for personal data security
Governance Procedures
Accountability and Compliance
Due to the nature, scope, context and purposes of processing undertaken by the IMF Bisou Bisou, we carry out frequent risk assessments and information audits to identify, assess, measure and monitor the impact of such processing. We have also implemented adequate and appropriate technical and organizational measures to ensure the safeguarding of personal data and compliance with the data protection laws and any codes of conduct that we have obligations under.
Our main governance objectives are to: - Educate senior management and employees about the requirements under the data protection laws and the possible impact of non-compliance
- Provide a dedicated and effective data protection training program for all staff
- Identify key senior stakeholders to support the data protection compliance program
- Allocate responsibility for data protection compliance and ensure that the designated person has sufficient access, support and budget to perform the role
- Identify, create and disseminate the reporting lines within the data protection governance structure
The technical and organizational measures that the Company has in place to ensure and demonstrate compliance with the data protection laws, regulations and codes of conduct, are detailed in this document and associated policies.
Privacy By design
We operate a 'Privacy by Design' approach and ethos, with the aim of mitigating the risks associated with processing personal data through prevention via our processes, systems and activities. IMF Bisou Bisou therefore has additional measures in place to adhere to this ethos, including: -
Data Minimization
Under Article 5 of the data protection laws, principle (c) advises that data should be 'limited to what is necessary', which forms the basis of our minimal approach. We only ever obtain, retain, process and share the data that is essential to carry out our services and legal obligations and we only keep if for as long as is necessary.
Our systems, employees, processes and activities are designed to limit the collection of personal information to that which is directly relevant and necessary to accomplish the specified purpose. Data minimization enables us to reduce data protection risks and breaches and supports our compliance with the data protection laws.
Measures to ensure that only the necessary data is collected includes:
- Electronic collection (i.e. forms, website, surveys etc.) only have the fields that are relevant to the purpose of collection and subsequent processing. We do not include 'optional' fields, as optional denotes that it is not necessary to obtain
- Physical collection (i.e. face-to-face, telephone etc.) is supported using scripts and internal forms where the required data collection is ascertained using predefined fields. Again, only that which is relevant and necessary is collected
- IMF Bisou Bisou has SLA's and bespoke agreements in place with third-party controllers who send us personal information. These state that only relevant and necessary data is to be provided as it relates to the processing activity we are carrying out.
- IMF Bisou Bisou has documented destruction procedures in place where a data subject or third-party provides us with personal information that is surplus to requirement.
Pseudonymisation
IMF Bisou Bisou utilizes pseudonymisation where possible to record and store personal data in a way that ensures data can no longer be attributed to a specific data subject without the use of separate additional information (personal identifiers).
Encryption and partitioning is also used to protect the personal identifiers, which are always kept separate from the pseudonymised data sets. When using pseudonymisation, we ensure that the attribute(s) being removed and replaced, are unique and prevent the data subject from being identified through the remaining markers and attributes.
Pseudonymisation means that the data subject is still likely to be identified indirectly and as such, we use this technique in conjunction with other technical and operational measures of risk reduction and data protection.
Encryption
Although IMF Bisou Bisou classifies encryption as a form of pseudonymisation, we also utilize it as a secondary risk prevention measure for securing the personal data that held. Encryption with a secret key is used to make data indecipherable unless decryption of the dataset is carried out using the assigned key. IMF Bisou Bisou utilizes encryption via secret key for transferring personal data to any external party and provide the secret key in a separate format. Where special category information is being transferred and/or disclosed, the Data Protection Officer is required to authorize the transfer and review the encryption method for compliance and accuracy.
Restriction
Our Privacy by Design approach means that we use company-wide restriction methods for all personal data activities. Restricting access is built into the foundation of IMF Bisou Bisou’s processes, systems and structure and ensures that only those with authorization and/or a relevant purpose, have access to personal information
Hard Copy Data
Due to the nature of our business, it is sometimes essential for us to obtain, process and share personal and special category information which is only available in a paper format without pseudonymisation options (i.e. copies of patient records, hospital invoices or claims information).
Where this is necessary, we utilize a tiered approach to minimize the information we hold and/or the length of time we hold it for. Steps include:
- In the first instance, we always ask the initial data controller to send copies of any personal information records directly to the data subject
- Where step 1 is not possible or feasible, we will obtain a copy of the data and if applicable redact to ensure that only the relevant information remains (i.e. when the data is being passed to a third-party for processing and not directly to the data subject)
- When only mandatory information is visible on the hard copy data, we utilize electronic formats to send the information to the recipient to ensure that encryption methods can be applied (i.e. we do not use the postal system as this can be intercepted).
- Recipients (i.e. the data subject, third-party processer) are verified and their identity and contact details checked
- The Data Protection Officer authorizes the transfer and checks the file(s) attached and encryption method and key
- Once confirmation has been obtained that the recipient has received the personal information, where possible (within the legal guidelines and rules of the data protection laws), we destroy the hard copy data and delete the sent message
- If for any reason a copy of the paper data must be retained by IMF Bisou Bisou, we use a physical safe to store such documents as oppose to our standard archiving system
Information Audit
To enable IMF Bisou Bisou to fully prepare for and comply with the data protection laws, we have carried out a company-wide data protection information audit to better enable us to record, categorize and protect the personal data that we hold and process.
The audit has identified, categorized and recorded all personal information obtained, processed and shared by our company in our capacity as a controller/processor and has been compiled on a central register which includes:
- What personal data we hold
- Where it came from
- Who we share it with
- Legal basis for processing it
- What format(s) is it in
- Who is responsible for it?
- Disclosures and Transfers
Legal Basis for Processing
Prior to carrying out any processing activity on personal information, IMF Bisou Bisou always identify and establish the legal basis for doing so and verify these with the regulations.
Data is only obtained, processed or stored when we have met the lawfulness of processing requirements, where:
- The data subject has given consent to the processing of their personal data for one or more specific purposes
- Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract
- Processing is necessary for compliance with a legal obligation to which we are subject
- Processing is necessary in order to protect the vital interests of the data subject or of another natural person
- Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Company
- Processing is necessary for the purposes of the legitimate interests pursued by IMF Bisou Bisou or by a third party (except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child).
Processing Special Category Data
Special categories of Personal Data are defined in the data protection laws as: - Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited – unless one of the Article 9 clauses applies.
IMF Bisou Bisou will not any process special Data Category
Data Retention and Disposal
IMF Bisou Bisou has defined procedures for adhering to the retention periods as set out by the relevant laws, contracts and business requirements, as well as adhering to the data protection laws requirement to only hold and process personal information for as long as is necessary. All personal data is disposed of in a way that protects the rights and privacy of data subjects (e.g. shredding, disposal as confidential waste, secure electronic deletion) and prioritizes the protection of the personal data at all times.
Audit and Monitoring
This policy and procedure document details the extensive controls, measures and methods used by IMF Bisou Bisou to protect personal data, uphold the rights of data subjects, mitigate risks, minimize breaches and comply with the data protection laws and associated laws and codes of conduct. In addition to these, we also carry out regular audits and compliance monitoring processes that are detailed in our Compliance Monitoring & Audit Policy & Procedure, with a view to ensuring that the measures and controls in place to protect data subjects and their information, are adequate, effective and compliant at all times.
The Data Protection Officer has overall responsibility for assessing, testing, reviewing and improving the processes, measures and controls in place and reporting improvement action plans to the Senior Management Team where applicable. Data minimization methods are frequently reviewed and new technologies assessed to ensure that we are protecting data and individuals to the best of our ability.
All reviews, audits and ongoing monitoring processes are recorded by the Data Protection Officer and copies provided to Senior Management and are made readily available to the Supervisory Authority where requested.
The aim of internal data protection audits is to: -
- Ensure that the appropriate policies and procedures are in place
- To verify that those policies and procedures are being followed
- To test the adequacy and effectiveness of the measures and controls in place
- To detect breaches or potential breaches of compliance
- To identify risks and assess the mitigating actions in place to minimize such risks
- To recommend solutions and actions plans to Senior Management for improvements in protecting data subjects and safeguarding their personal data
- To monitor compliance with the data protection laws and demonstrate best practice
Responsibilities
IMF Bisou Bisou will appointed a Data Protection Officer whose role it is to identify and mitigate any risks to the protection of personal data, to act in an advisory capacity to the business, its employees and upper management and to actively stay informed and up-to-date with all legislation and changes relating to data protection. The DPO will work in conjunction with the IT Manager and IT Team to ensure that all processes, systems and staff are operating compliantly and within the requirements of the data protection laws and its principles.
The DPO has overall responsibility for due diligence, privacy impact assessments, risk analysis and data transfers where personal data is involved and will also maintain adequate and effective records and management reports in accordance with the data protection laws and our own internal objectives and obligations.